Skip to content

Responding to Non-Compliance with Laws and Regulations (NOCLAR)

VIVA Subject Guide
YouTube video

1 Introduction

This chapter deals with how the auditor should respond to a client’s failure to comply with laws and regulations. Potentially, non-compliance will lead to fines, penalties and damages and these should be recognised as liabilities or contingent liabilities. Additionally, non-compliance might cause going concern issues if the company is then prohibited from trading or the non-compliance damages the reputation of the company to such an extent that its survival is threatened.

ISA 250 Consideration of Laws and Regulations in the Audit of Financial Statements is relevant. In addition, IESBA's pronouncement Responding to Non-Compliance with Laws and Regulations (NOCLAR) provides a framework for how professional accountants should act in the public interest, when they become aware of or suspect NOCLAR.

NOCLAR is defined as acts of commission or omission, intentional or unintentional, committed by a client or TCWG... contrary to laws or regulations. The definition excludes personal misconduct (i.e. unrelated to business activities).

The ethical standard permits accountants to set aside the duty of confidentiality in order to disclose NOCLAR rather than simply resign.

2 Management’s and auditor’s responsibilities

ISA 250 states that “It is the responsibility of management, with the oversight of those charged with governance, to ensure that the entity’s operations are conducted in accordance with the provisions of laws and regulations, including compliance with the provisions of laws and regulations that determine reported amounts and disclosures in an entity’s financial statements”.

Management’s responsibilities will be easier to meet if there is an effective system of internal controls, an internal audit department and an audit committee.

ISA 250 also states “the auditor is not responsible for preventing non-compliance and cannot be expected to detect non-compliance with all laws and regulations”.

However, overall the auditor is responsible for identifying material misstatements whether caused by fraud or error but the ISA recognises that the risk of the auditor failing to detect material misstatements arising because of non-compliance can be increased because:

  • There are many laws and regulations that do not directly affect the financial statements.

  • Non-compliance might be accompanied by deliberate concealment.

  • Whether an act amounts to non-compliance is ultimately a matter for the court or regulators.

ISA 250 distinguishes the auditor’s responsibilities for compliance between two categories of laws and regulations:

  • Those that have a direct effect on the financial statements (eg tax and pension laws). Here, the auditor must obtain sufficient appropriate audit evidence regarding compliance with these laws. This is, essentially a positive confirmation.

  • Those that do not have a direct effect on the financial statements, but may be fundamental to business operations, going concern or the avoidance of material penalties. Here, the auditor’s responsibility is limited to undertaking procedures to help the identification of non-compliance where this could have a material effect on the financial statements. This is, essentially, a negative confirmation.

3 Audit procedures to assess compliance

  • Obtain an understanding of the client’s regulatory environment and how the client complies.

  • Obtain sufficient appropriate audit evidence where the laws and regulations directly affect the financial statements.

  • In respect of other laws:

    • enquire of management whether the entity is in compliance

    • inspect correspondence with relevant licensing authorities.

  • Remain alert during the audit that other audit procedures might detect non-compliance.

  • Ask for written representations from management declaring that all known incidents of non-compliance whose effects should be considered in the preparation of the financial statements have been disclosed to the auditor.

  • In the absence of identified or suspected non-compliance the auditor is not required to carry out audit procedures to confirm compliance other than those listed above.

4 Non-compliance is identified or suspected

The auditor must:

  • Understand the nature of the non-compliance and evaluate the possible effects on the financial statements.

  • Discuss the matter with management and TCWG if appropriate.

  • If sufficient information about the suspected non-compliance cannot be obtained, consider the effect of this lack of sufficient appropriate evidence on the audit opinion.

  • Consider the effects of non-compliance on other aspects of the audit such as risk assessment and the reliability of written representations. [In other words, the directors may have shown that they consider compliance to be voluntary. If they act like this in one area how many other incidents of non-compliance might exist?]

5 Reporting non-compliance

All incidents of non-compliance should be reported to TCWG (unless trivial).

If the auditor believes non-compliance is deliberate, this should be communicated to TCWG.

If TCWG are complicit in the non-compliance, and there is no higher level of authority (such as a parent's board or audit committee) then the auditor should take legal advice.

If non-compliance gives rise to material misstatement in the financial statements, the audit opinion will have to be modified (qualified or adverse)

If the auditor is prevented from investigating the matter, the audit opinion will have to be modified (qualified or disclaimer).

It is important that all discussions, findings and disclosures are well-documented as there is obviously a high risk to the auditor of fallout from these incidents.

Under the NOCLAR provisions in the IESBA standard the auditor should:

  • Advise management and TCWG to take timely and appropriate action to remedy or avert non-compliance.

  • Disclose the matter to the appropriate authority (unless precluded by law or regulation) for investigation and action to be taken in the public interest.

The auditor must assess management’s response then decide if further action is required in the public interest. Simply resigning from the engagement is NOT a substitute for taking appropriate further action. If, however, withdrawal is the only available course of action, the proposed successor should be informed of the matter (even without the former client's permission).

Whether the auditor should disclose the matter to the authorities depends on the actual or potential harm that might be done to investors, employees, general public and so on. Examples where disclosure is likely to be justified include:

  • Bribery

  • The sale of harmful products

  • Tax evasion

  • Behaviour likely to damage financial markets.

If the disclosure is made in good faith it will not be considered to be a breach of confidentiality.